A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
An attacker can remotely, without any authentication, send a crafted request to the /goform/form2lansetup.cgi endpoint, manipulating the 'ip' argument. Passing an excessively long value leads to a stack-based buffer overflow, which enables overwriting critical memory areas. The vulnerability results from the lack of proper input length validation before copying data into a fixed-size buffer.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code remotely (RCE) on the vulnerable device or cause its instability and unavailability. In the worst-case scenario, the attacker may gain full control over the router.
The D-Link manufacturer no longer issues updates for this model, as the product has reached End of Life status. Immediate replacement with an actively supported model is recommended. As a temporary security measure, isolate the device's administration panel from external network access and restrict access to the management interface only to trusted internal hosts.
D-Link DIR-816 with firmware version 1.10CNB05. Only applies to products that are no longer supported by the manufacturer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dir 816
HWDlinkall versionsDlink Dir 816 Firmware
OSDlink1.10cnb05
Related vulnerabilities
RCE w D-Link DIR-816-A2 przez podatną funkcję system() w goahead
Stack-based buffer overflow w D-Link DIR-816 — funkcja QoSPortSetup
Stack-based buffer overflow w D-Link DIR-816 — zdalny atak bez uwierzytelnienia
Stack-based buffer overflow w D-Link DIR-816 – funkcja qosClassifier
D-Link DIR-816: nieautoryzowana zmiana konfiguracji DMZ przez formDMZ.cgi